public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: Paolo Bonzini <pbonzini@redhat.com>
Cc: Sasha Levin <sashal@kernel.org>,
	linux-kernel@vger.kernel.org, cve@kernel.org,
	Jiri Kosina <jkosina@suse.cz>
Subject: Re: CVE-2023-52437: Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d"
Date: Wed, 21 Feb 2024 19:21:49 +0100	[thread overview]
Message-ID: <2024022129-expiring-resurface-146c@gregkh> (raw)
In-Reply-To: <3ebbc121-8cb8-4b8d-ad5d-fb5c576e5171@redhat.com>

On Wed, Feb 21, 2024 at 04:56:31PM +0100, Paolo Bonzini wrote:
> To recap:
> 
> - the CVE description comes from was upstream commit bed9e27baf52
> 
> - neither the CVE mitigation section nor the mentioned kernel releases
> fix the bug mentioned in the upstream commit, because the mitigation
> section also includes commits that _revert_ commit bed9e27baf52
> 
> - this second revert is not mentioned anywhere, so the CVE description
> is at best misleading; or perhaps more accurately described as
> "completely f***ed up".
> 
> I'm sure it's just a bug in the scripts, but it's worrisome that you
> don't acknowledge this.

Yes, this is a bug in the scripts, but it wasn't obvious what you were
objecting to here honestly.  Reverts were not anything I tested the
scripts with before now, and I'm sure there are going to be more cases
that fail in odd ways too.  We'll fix them when they show up, that's the
best we can do.

I'll look at it tomorrow and try to figure it out, if nothing else, I'll
just manually update the json record and push the update to cve.org as
that's the "canonical" record here.  The json files will be updated over
time as new releases happen and patches flow backwards, so they will be
updated, but for now, sending out new email messages all the time would
be a mess.

However in this case, I'll fix it up and send out a new announcement as
obviously it's wrong in places.

If you want to replace the wording in the description here with anything
else better, PLEASE let us know and we will be glad to do so.

That's the benifit of being a CNA, we can ACTUALLY MODIFY the CVE
records, previously it was almost impossible to ever do so.

thanks,

greg k-h

  parent reply	other threads:[~2024-02-21 18:21 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <2024022009-subsoil-halt-4b28@gregkh>
2024-02-21  9:09 ` CVE-2023-52437: Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d" [resend] Paolo Bonzini
     [not found]   ` <CABgObfYDcFPRNpGtsY=UbstXbqVCMcxy3LPS_xJ65aFcByC=Nw@mail.gmail.com>
     [not found]     ` <ZdXt09vL4GJy6PbP@sashalap>
     [not found]       ` <0e8675e0-165d-4cf7-9755-666278868ab8@redhat.com>
     [not found]         ` <ZdX2LcAWR6wyvYC5@sashalap>
     [not found]           ` <bec7c1db-c13e-4b00-a968-4ae69539d7ac@redhat.com>
2024-02-21 14:35             ` CVE-2023-52437: Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d" Sasha Levin
2024-02-21 15:02               ` Paolo Bonzini
2024-02-21 15:11                 ` Sasha Levin
2024-02-21 15:56                   ` Paolo Bonzini
2024-02-21 16:22                     ` Sasha Levin
2024-02-21 18:09                       ` Paolo Bonzini
2024-02-21 18:21                     ` Greg Kroah-Hartman [this message]
2024-02-22  9:58                       ` Paolo Bonzini
2024-02-22 12:55                         ` Greg Kroah-Hartman
2024-02-22 13:31                           ` Paolo Bonzini
2024-02-29  5:32                             ` Greg Kroah-Hartman
2024-02-29  6:05                               ` Greg Kroah-Hartman
2024-02-29 10:53                                 ` Paolo Bonzini
2024-02-29 20:05                                   ` Greg Kroah-Hartman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2024022129-expiring-resurface-146c@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=jkosina@suse.cz \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=sashal@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox